Re: Opportunistic signatures - a proposed design

Jonathan Morton <[email protected]>
Newsgroups gmane.mail.spam.hashcash
Message-ID <[email protected]>
> a practical implementation of a system using shared secrets would be 
> an absolute nightmare on anything approaching the scale of email. if 
> anyone can explain a feasible (secure, trusted, invisible to end 
> users, etc) system of key exchange, i'd enjoy hearing about it.

I think I've already described it.  Let me go over your points one by 
one:

- Scalability.  Each key is known only to it's singular sender and 
singular recipient.  There is no central authority of any kind, and no 
need to send revocation notice to multiple people.  Therefore it will 
scale indefinitely.

- Security.  The key is sent across the wire once (in the common case), 
in plaintext.  This is considerably more secure than the subsequent 
storage of the key on the participating computers, in today's Internet, 
and I believe this is sufficient.

- Trusted.  Each key is only accepted into the recipient's whitelist if 
it comes with high-value hashcash *and* the recipient has already sent 
mail to the sender.  This establishes that a consensual two-way 
conversation is in progress, which is the entire point of the exercise.

- Invisible.  Yes, it is.

--------------------------------------------------------------
from:     Jonathan "Chromatix" Morton
mail:     [email protected]
website:  http://www.chromatix.uklinux.net/
tagline:  The key to knowledge is not to rely on people to teach you it.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.